A large‑scale cyberattack on Berlin’s Lichtenberg district prompted emergency measures on Wednesday, and the US firm hired by the city‑state Senate to manage the district’s IT infrastructure has declined to provide the authorities with system access, raising alarms over the city’s digital security posture.
Attack and Immediate Impact
According to Tagesspiegel, the breach targeted the district’s computer networks, disrupting municipal services and prompting an urgent response from local officials. While the exact scope of the intrusion has not been disclosed, the incident forced Lichtenberg’s administration to suspend several online portals pending a security review.
US Contractor’s Role and Refusal
The IT services contract was awarded by the Berlin Senate, the governing body of the capital, to a US‑based company specializing in public‑sector cybersecurity. In the wake of the attack, the contractor has reportedly refused to grant the Senate’s technical teams direct access to the compromised systems, citing contractual and liability concerns.
The US contractor commissioned by the Senate has refused to grant IT access following the attack.
Political and Public Reaction
Berlin’s Senate, led by Governing Mayor Franziska Giffey, expressed disappointment and demanded immediate clarification from the contractor. Opposition parties and local civic groups have called for a transparent audit of all foreign‑run IT contracts, warning that reliance on external providers could expose critical public services to similar threats.

Security analysts, speaking on condition of anonymity, warned that the contractor’s refusal could hamper forensic investigations, delay remediation, and undermine public confidence in the city’s digital infrastructure. They emphasized that German data‑protection laws require swift cooperation from any entity handling public data, especially after a breach.
Broader Implications for German IT Policy
The Lichtenberg incident arrives amid a broader European debate on the use of non‑EU service providers for governmental IT systems. German authorities have recently tightened oversight of foreign‑owned contractors, aiming to align with the EU’s Cybersecurity Act and the General Data Protection Regulation (GDPR). This case may accelerate calls for stricter vetting procedures and greater in‑house capabilities.
Federal police and the Federal Office for Information Security (BSI) have been notified and are expected to join the investigation. The Senate has announced plans to review the existing contract, consider alternative providers, and develop a contingency framework to ensure continuity of essential digital services in future incidents.

As the investigation proceeds, Berlin’s administration faces mounting pressure to balance rapid response with legal and contractual obligations, while safeguarding the privacy and functionality of its citizens’ digital interactions.